4d26453a0b
Re-introduces the per-tool approval system from luzidd's commit 39124f3 (which is no longer reachable from main) and improves it before re-landing. What's restored: - ApprovalPolicy (allow/deny/prompt) plus DEFAULT_APPROVAL_POLICIES. - ACTION_EXCEPTIONS registry (LSP read-only, bash critical patterns). - getApprovalPolicy() six-level resolution order. - ExtensionToolWrapper.execute() gate before extension handlers. - --auto-approve / --yolo CLI flag and tools.approval.<tool> user config. - docs/approval-mode.md user guide. What's improved over the original: - Replaced unchecked 'as any' casts with typed unknown narrowing helpers. - Validate userConfig values: invalid strings, numbers, etc. fall through to the built-in default instead of being silently honoured (typo no longer locks a tool out or grants implicit approval). - Expanded CRITICAL_BASH_PATTERNS: chmod -R /, chown -R /, bash <(curl ...), writes to /etc/passwd|shadow|sudoers, shutdown/reboot/halt/init 0, kill -9 1, nc -e / nc -c reverse shells. Pattern shapes require a command-position boundary so 'npm run reboot-tests' and 'echo "shutdown the queue"' don't false-positive. - Added DEBUG_READONLY_ACTIONS exception so DAP inspection actions (threads, stack_trace, variables, scopes, read_memory, …) auto-allow while execution-side actions (launch, attach, continue, evaluate, write_memory, set_breakpoint, …) still prompt. - formatApprovalPrompt: labels mcp__<server>__<tool> calls as MCP server tools, surfaces ssh host + command, recognises the modern § hashline header for edit, and truncates >240-char fields so a heredoc-sized body cannot blow out the confirmation dialog. - Test suite grown from 40 to 57 cases — new coverage for invalid user config, the extended critical-bash patterns, benign-keyword negatives, debug exceptions, MCP/ssh prompt formatting, and command truncation. Verification: - bun test packages/coding-agent/test/tools/approval.test.ts -> 57 pass - bun x biome check . -> clean - bun run check:ts across all 9 workspaces -> clean